T08 · Insecure Dependencies
- Location
scripts/openclaw-safe-update.sh:122- Finding
Unverified npm Package Code Can Execute with Elevated Privileges
- Content
View full analysis
/dev/null CANDIDATE_ENTRY="$CANDIDATE_DIR/node_modules/openclaw/dist/index.js" [[ -f "$CANDIDATE_ENTRY" ]] || fail "Candidate entry not found: $CANDIDATE_ENTRY" echo "[4/7] Starting sidecar (profile=$SIDECAR_PROFILE, port=$SIDECAR_PORT)..." rm -f "$SIDECAR_LOG" "$NODE_BIN" "$CANDIDATE_ENTRY" --profile "$SIDECAR_PROFILE" gateway --port "$SIDECAR_PORT" --bind "$SIDECAR_BIND" >"$SIDECAR_LOG" 2>&1 & ``` ```bash echo "[7/7] Applying global upgrade + restarting gateway..." $NPM_BIN install -g "openclaw@$LATEST_VERSION" --no-audit --no-fund --loglevel=error >/dev/null ``` The Linux guide recommends elevating the entire script: ```bash # if policy allows and system npm requires it sudo bash scripts/openclaw-safe-update.sh --apply ``` ### Technical Analysis When no explicit target is supplied, the updater obtains a mutable version value from the configured npm registry and installs that package directly. It does not enforce the official registry, compare the downloaded ...[truncated 2187 chars]- Remediation
View remediation
